Posts

Showing posts with the label Russia

Massive SMS stealer campaign infects Android devices in 113 countries

Image
By Bill Toulas,  Bleeping Computer A malicious campaign targeting Android devices worldwide utilizes thousands of Telegram bots to infect devices with SMS-stealing malware and steal one-time 2FA passwords (OTPs) for over 600 services. Zimperium researchers discovered the operation and have been tracking it since February 2022. They report finding at least 107,000 distinct malware samples associated with the campaign. The cybercriminals are motivated by financial gain, most likely using infected devices as authentication and anonymization relays. Telegram entrapment The SMS stealer is distributed either through malvertising or Telegram bots that automate communications with the victim. In the first case, victims are led to pages mimicking Google Play, reporting inflated download counts to add legitimacy and create a false sense of trust. On Telegram, the bots promise to give the user a pirated application for the Android platform, asking for their phone number before they share the ...

CISA orders agencies impacted by Microsoft hack to mitigate risks

Image
By Sergiu Gatlan, Bleeping Computer CISA has issued a new emergency directive ordering U.S. federal agencies to address risks resulting from the breach of multiple Microsoft corporate email accounts by the Russian APT29 hacking group. Emergency Directive 24-02 was issued to Federal Civilian Executive Branch (FCEB) agencies on April 2. It requires them to investigate potentially affected emails, reset any compromised credentials (if any), and take measures to secure privileged Microsoft Azure accounts. CISA says Russian Foreign Intelligence Service (SVR) operatives now use information stolen from Microsoft's corporate email systems, including the authentication details shared between Microsoft and its customers by email, to gain access to certain customer systems. "This Emergency Directive requires immediate action by agencies to reduce risk to our federal systems. For several years, the U.S. government has documented malicious cyber activity as a standard part of the Russian ...

Ukraine claims it hacked Russian Ministry of Defense servers

Image
By Bill Toulas,  Bleeping Computer The Main Intelligence Directorate (GUR) of Ukraine's Ministry of Defense claims that it breached the servers of the Russian Ministry of Defense (Minoborony) and stole sensitive documents. A press release published today on an official Ukrainian government domain describes the attack as a "special operation" carried out by GUR's cyber-specialists. As a result of the breach, the GUR claims to have obtained sensitive documents that contain secret service information, including: Software used by the Russian Ministry of Defense for protecting and encrypting data An array of secret service documents from the Russian Ministry of Defense, including orders, reports, directives, and various other documents, circulated among over 2000 structural units of the ministry. Information that allows establishing the complete structure of the system of the Minoborony and its links. Data that helped identify senior heads of structural units of the Minobo...

Health insurance data breach affects nearly half of France’s population, privacy regulator warns

Image
By Alexander Martin, TheRecord.Media Data on more than 33 million people in France, approximately half the population, was compromised in a cyberattack at the end of January, according to the country’s privacy watchdog. The Commission Nationale Informatique et Libertés (CNIL) announced this week it had been informed by two health insurance companies, Viamedis and Almerys, about the incident. It warned that the data affects policyholders and their families and includes “marital status, date of birth and social security number, the name of the health insurer as well as the guarantees of the contract taken out.” Fortunately, unlike the incident affecting Australian health insurance business Medibank , medical histories and treatment data was not compromised. The CNIL said that the health insurance companies were directly responsible for informing the affected individuals — but people are urged to be cautious over potential phishing attempts intending to defraud them. The CNIL warned tha...

EU warns of Russian cyberattack spillover, escalation risks

By Sergiu Gatlan,  Bleeping Computer The Council of the European Union (EU) said today that Russian hackers and hacker groups increasingly attacking "essential" organizations worldwide could lead to spillover risks and potential escalation. "This increase in malicious cyber activities, in the context of the war against Ukraine, creates unacceptable risks of spillover effects, misinterpretation and possible escalation," the High Representative on behalf of the EU said Tuesday. "The latest distributed denial-of-service (DDoS) attacks against several EU Member States and partners claimed by pro-Russian hacker groups are yet another example of the heightened and tense cyber threat landscape that EU and its Member States have observed." In this context, the EU reminded Russia that all United Nations member states must adhere to the UN's Framework of responsible state behavior in cyberspace to ensure international security and peace. The EU urged all states ...

Microsoft Shows Its Power Against Russia

By Ellen Chang,  The Street Tech giant Microsoft  (MSFT) - Get Microsoft Corporation Report provided tech and monetary assistance to Ukraine as it fought against cyber attacks from Russia.  The company made both financial and technological commitments to Ukraine as it was invaded by Russia in February. Microsoft promised a total of $239 million in assistance, including $107 million to "literally move the government and much of the country of Ukraine from on-premises servers to the cloud," Microsoft President Brad Smith said in an interview with GeekWire last week at his office in Redmond, Washington. The Russian government has engaged in malicious cyber activities to suppress various political and social activity, according to the Cybersecurity and Infrastructure Security Agency (CISA). The Russian state-sponsored cyber actors have the ability to "compromise IT networks; develop mechanisms to maintain long-term, persistent access to IT networks; exfiltrate sensitive data...

Russian Hackers Continue Brutal Ukraine Cyber-Assault But Microsoft Is Fighting Back

By Nathan Wasson,  Hot Hardware Shortly after Russia invaded Ukraine near the beginning of this year, some prominent hacking groups announced that they would be joining the war within the digital realm. The hacking collective Anonymous declared cyberwar against the Russian government and has since been conducting cyberattacks on Russian and Belarusian government websites, news channels, and military operations systems. On the other side of the conflict is the Conti ransomware gang, which announced its full support of the Russian government and intention to strike back against Western cyber operations. The Russian-speaking ransomware group has since broken up and abandoned the Conti name, but other Russian-based hacking groups are still conducting cyberattacks on Ukraine and its Western allies. Microsoft is also participating in the conflict by joining the ongoing sanctions on Russia. Microsoft halted sales in Russia near the outset of the war, but, just last week, Microsoft began b...

Russia is well-prepared for cyber war

by Jurgita LapienytÄ—,  Cybernews For the first time ever, we are witnessing a real cyber war, Denys Tsvaig, the president of Ukraine’s national cybersecurity association, told Cybernews. The war in Ukraine caused turmoil in the cyber realm, with many pro-Ukrainian and pro-Russian citizens worldwide joining various efforts to fight. Hacktivism gained momentum soon after the invasion, causing collateral damage. Recently, the pro-Russian Killnet group made headlines after attacking Ukraine ally Lithuania’s websites in response to the Baltic country following EU sanctions. Hacktivism aside, Ukraine and Russia have used cyber weapons to support their kinetic operations. For example, Russia resorted to disinformation before many major military strikes. In its turn, Ukraine allegedly was able to cause some physical damage to Russian infrastructure using its IT resources, as unverified reports say. Some say Russia’s cyber weapons are just as weak as its artillery. The State Service of Spec...

Pro-Russia hackers claim responsibility for 'intense, ongoing' cyberattack against Lithuanian websites

By Sean Lyngaas, CNN An "intense, ongoing" cyberattack has hit the websites of government agencies and private firms in Lithuania, the Baltic country's defense ministry said Monday. A Russian-speaking hacking group, known as Killnet , claimed responsibility for at least some of the hacks, saying they were in retaliation for Lithuania blocking the shipment of some goods to the Russian enclave of Kaliningrad, which is wedged between Lithuania and Poland. Monday's cyberattacks were aimed in part at Lithuania's Secure Data Transfer Network, a communications network for government officials that is built to withstand war and other crises, according to the defense ministry. "Part of the Secure National Data Transfer Network users have been unable to access services, work is in progress to restore it to normal," Lithuania's National Cyber Security Centre (NKSC) said in a statement issued by the defense ministry. "It is highly probable that such, or eve...

Russian govt hackers hit Ukraine with Cobalt Strike, CredoMap malware

By Bill Toulas,  Bleeping Computer The Ukrainian Computer Emergency Response Team (CERT) is warning that Russian hacking groups are exploiting the Follina code execution vulnerability in new phishing campaigns to install the CredoMap malware and Cobalt Strike beacons. The APT28 hacking group is believed to be sending emails containing a malicious document name "Nuclear Terrorism A Very Real Threat.rtf.". The threat actors selected the topic of this email to entice recipients to open it, exploiting the fear that's spread among Ukrainians about a potential nuclear attack. Threat actors also used a similar tactic in May 2022, when CERT-UA identified the dissemination of malicious documents warning about a chemical attack. The RTF document used in the APT28 campaign attempts to exploit CVE-2022-30190, aka "Follina," to download and launch the CredoMap malware (docx.exe) on a target's device. This vulnerability is a flaw in the Microsoft Diagnostic Tool, exploite...

More cyber warfare with Russia lies on the horizon

By Loukia Papadopoulos,  Interesting Engineering What is on the horizon in Russia's war plans? According to Neal Higgins, deputy national cyber director for national cybersecurity, there could be more cyber warfare. The cybersecurity professional spoke to DefenseNews on June 14 at an event hosted by Defense One and had some pretty revealing comments.

Russian state hackers swap malware with cloud-based attacks

By Vilius Petkauskas,  Cybernews Russian adversaries increasingly focus on targeting the cloud environment, Crowdstrike’s Global Threat Report on Cloud Security revealed. Fancy Bear, a Russian adversary associated with Russia’s Main Intelligence Directorate (GRU), used to rely on malware-based spear-phishing attacks, the report claims. However, with their tactics exposed by the US Department of Justice (DoJ), hackers have refocused their attention on cloud service providers. Since Fancy Bear’s primary source of intelligence comes from various credential harvesting practices that allow penetrating target organizations and individuals, it’s no surprise that the main targets are cloud-based email providers. According to the report, Fancy Bear focused their attention on service providers such as Microsoft 365, Google’s GSuite, as well as webmail providers that individuals usually use. Meanwhile, Cozy Bear, Russia’s state-sponsored hacker group controlled by the Federal Security service...

Russian hackers start targeting Ukraine with Follina exploits

By Bill Toulas,  Bleeping Computer Ukraine's Computer Emergency Response Team (CERT) is warning that the Russian hacking group Sandworm may be exploiting Follina, a remote code execution vulnerability in Microsoft Windows Support Diagnostic Tool (MSDT) currently tracked as CVE-2022-30190. The security issue can be triggered by either opening or selecting a specially crafted document and threat actors have been exploiting it in attacks since at least April 2022. It is worth noting that Ukraine's agency assesses with medium confidence that behind the malicious activity is the Sandworm hacker group.

Google terminates coordinated influence operations linked to Russia, China, and Costa Rica

by Anna Zhadan,  Cyber News The technology giant terminated hundreds of YouTube and Ads accounts for their involvement in coordinated influence operations designed to support Russia’s invasion of Ukraine, criticize Costa Rican politicians, and upload spam content. Google’s Threat Analysis Group (TAG) updated a bulletin for the second quarter of 2022 detailing all coordinated influence operation campaigns terminated on Google’s platforms over that period. This comes as a part of the platform's initiative to prevent the spread of misinformation and disinformation. As such, TAG terminated 138 YouTube channels and two Ads accounts for a campaign linked to a Russian consulting firm. The campaign praised Russia’s aggression in Ukraine and expressed critical views of Ukraine and the NATO alliance, disseminating content in Russian. Similarly, 44 YouTube channels and nine Ads accounts were removed for another campaign linked to the Internet Research Agency (IRA.) The channels were supporti...

Hacked Russian radio station broadcasts Ukrainian anthem

By Rachel Pannett and Brittany Shammas, Washington Post A Russian radio station’s news bulletin was interrupted Wednesday by the Ukrainian anthem and antiwar songs, in the latest example of Russian media outlets apparently being targeted by antiwar hackers. Kommersant FM’s online broadcast suddenly began playing the Ukrainian patriotic song “Oh, the Red Viburnum in the Meadow,” BBC Monitoring reporter Francis Scarr wrote on Twitter. The station’s editor in chief, Alexei Vorobyov, confirmed the incident to the Russian state-owned news agency Tass, saying it appeared the internet stream had been hacked. He said technicians were investigating the origin of the attack. While apparently under the control of hackers, the station also played the Ukrainian national anthem and the song “We Don’t Need War” by the Russian rock band Nogu Svelo. The station is owned by Uzbek-born billionaire Alisher Usmanov, who was sanctioned by the United States and the European Union following the invasion for h...

Russia says West risks ‘direct military clash’ over cyberattacks

By Reuters Russia warned the West on Thursday that cyber attacks against its infrastructure risked leading to direct military confrontation, and that attempts to challenge Moscow in the cyber sphere would be met with targeted countermeasures. The warning comes after Russia’s housing ministry website appeared to be hacked over the weekend, with an internet search for the site leading to a “Glory to Ukraine” sign in Ukrainian. In a statement, the foreign ministry said that Russia’s critical infrastructure and state institutions were being hit by cyberattacks and pointed to figures in the United States and Ukraine as being responsible. “Rest assured, Russia will not leave aggressive actions unanswered,” it said. “All our steps will be measured, targeted, in accordance with our legislation and international law.” The statement, issued by the ministry’s head of international information security, said Washington was “deliberately lowering the threshold for the combat use” of cyberweaopns. “...

US Government Ordered Travel Companies To Spy On Russian Hacker For Years And Report His Whereabouts Every Week

Image
By Thomas Brewster, Forbes In 2015, the U.S. Secret Service was on the hunt for Aleksei Burkov, an infamous Russian hacker suspected of facilitating the theft of $20 million from stolen credit cards on the Cardplanet website. The methods the agency used to pursue him, revealed for the first time as a result of a Forbes legal challenge, show how the U.S. government was able to strong-arm two data companies into spying on him for two years based on the authority of a 233-year-old law and to issue weekly reports on his whereabouts. The government has never disclosed how many other individuals could be under such prolonged and unconventional surveillance. The two companies, Sabre in the U.S. and Travelport in the U.K., were perfect suppliers to American law enforcement because of the business they’re in. For decades, they’ve been collecting and storing information about international tourists in a so-called global distribution system. GDSs are essentially hubs of information that make trav...

Wray: FBI blocked planned cyberattack on children’s hospital

By Eric Tucker & Alan Suderman, NBC The FBI thwarted a planned cyberattack on a children’s hospital in Boston that was to have been carried out by hackers sponsored by the Iranian government, FBI Director Christopher Wray said Wednesday. Wray told a Boston College cybersecurity conference that his agents learned of the planned digital attack from an unspecified intelligence partner and got Boston Children’s Hospital the information it needed last summer to block what would have been “one of the most despicable cyberattacks I’ve seen.” “And quick actions by everyone involved, especially at the hospital, protected both the network and the sick kids who depended on it,” Wray said. The FBI chief recounted that anecdote in a broader speech about cyber threats from Russia, China and Iran, and the need for partnerships between the U.S. government and the private sector. He said the bureau and Boston Children’s Hospital had worked closely after a hacktivist attacked the hospital’s computer...

Costa Rica May Be Pawn in Conti Ransomware Group’s Bid to Rebrand, Evade Sanctions

By  Krebs On Security Costa Rica’s national health service was hacked sometime earlier this morning by a Russian ransomware group known as Hive . The intrusion comes just weeks after Costa Rican President Rodrigo Chaves declared a state of emergency in response to a data ransom attack from a different Russian ransomware gang — Conti . Ransomware experts say there is good reason to believe the same cybercriminals are behind both attacks, and that Hive has been helping Conti rebrand and evade international sanctions targeting extortion payouts to cybercriminals operating in Russia. The Costa Rican publication CRprensa.com reports that affected systems at the Costa Rican Social Security Fund (CCSS) were taken offline on the morning of May 31, but that the extent of the breach was still unclear. The CCSS is responsible for Costa Rica’s public health sector, and worker and employer contributions are mandated by law. A copy of the ransom note left behind by the intruders and subsequen...

Russian hackers perform reconnaissance against Austria, Estonia

By Bill Toulas, Bleeping Computer In a new reconnaissance campaign, the Russian state-sponsored hacking group Turla was observed targeting the Austrian Economic Chamber, a NATO platform, and the Baltic Defense College. This discovery comes from cybersecurity firm Sekoia, which built upon previous findings of Google’s TAG , which has been following Russian hackers closely this year. Google warned about coordinated Russian-based threat group activity in late March 2022, while in May, they spotted two Turla domains used in ongoing campaigns. Sekoia used this information to investigate further and found that Turla targeted the federal organization in Austria and the military college in the Baltic region.